76 to 100 of 809 ISO/IEC 27001 Jobs in London

IT Security Compliance & Reporting Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Salary
£ 100 K
ISO 27001 and NIST CSF.Experience producing security compliance reporting, MI or dashboards, ideally using Power BI.Experience managing or supporting IT / security risk registers and risk assessments.An understanding of IT security controls and disciplines, including vulnerability management, patching, identity and access management, privileged access management … approach to identifying gaps, risks and opportunities for improvement.Relevant certifications such as CISSP, CISM, CRISC or ISO 27001 Lead Auditor / Implementer would be advantageous.In return for your commitment, you can expectAt Ricoh, work should feel meaningful, supportive and fulfilling. The Ricoh Promise shapes your ...

IT Security Compliance & Reporting Analyst

Hiring Organisation
Ricoh
Location
London, UK
Employment Type
Full-time
ISO 27001 and NIST CSF.Experience producing security compliance reporting, MI or dashboards, ideally using Power BI.Experience managing or supporting IT / security risk registers and risk assessments. An understanding of IT security controls and disciplines, including vulnerability management, patching, identity and access management, privileged access … identifying gaps, risks and opportunities for improvement. Relevant certifications such as CISSP, CISM, CRISC or ISO 27001 Lead Auditor / Implementer would be advantageous. In return for your commitment, you can expectAt Ricoh, work should feel meaningful, supportive and fulfilling. The Ricoh Promise shapes your ...

Product Delivery Lead

Location
Greater London, England, United Kingdom
enterprise‐grade product Experience working directly with large engineering teams on the roadmap, release planning, dependency mapping, and cross‐team sequencing Current programming / scripting experience and a familiarity with DevSecOps practices in order to drive automation without compromising quality or security Strong stakeholder communication skills when translating between … engineering, product, customer‐facing teams, and leadership Exposure to security and compliance frameworks (e.g. SOC 2 / ISO 9001 / ISO 27001) Ideally, you would also have: This is not an additional list of requirements; this reflects the tech stack currently used ...

Cyber Security Lead

Hiring Organisation
Chambers and Partners
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
information security matters to various stakeholders across the organisation. Oversee the day-to-day operation of security systems and tools, including firewalls, intrusion detection / prevention systems (IDS / IPS), antivirus, anti-malware, SIEM (Security Information and Event Management), vulnerability scanners, and data encryption solutions. Manage vulnerability management … maintenance of all IT infrastructure, including cloud environments (e.g., Azure, AWS, GCP), networks, servers, and endpoints. Manage access controls, identity management (e.g., Entra ID / Azure AD), and privileged access management (PAM) systems. Manage access control processes to 3rd party applications, and 3rd party relations. Oversee the patching ...

Expert Associate Partner, Architecture (Cybersecurity)

Hiring Organisation
Bain & Company
Location
London, United Kingdom
Salary
£ 80 K
project leadership team and represent security across business and technology workstreams.Manage and direct teams of architects and consultants day-to-day.Produce as-is / to-be security architecture documentation, risk assessments, and migration artefacts.Identify client opportunities, develop security-focused points of view, and support account expansion.Understand what clients … assessment; enterprise security programme design; and secure SDLC.Working knowledge of at least two cybersecurity frameworks: NIST CSF, NIST SP 800-53, ISO / IEC 27000 series, C2M2, or Cloud Security Alliance CCM.Familiarity with AI platform security, cloud and data security risks, and third-party / ...

Expert Associate Partner, Architecture (Cybersecurity)

Location
Greater London, England, United Kingdom
leadership team and represent security across business and technology workstreams. Manage and direct teams of architects and consultants day‐to‐day. Produce as‐is / to‐be security architecture documentation, risk assessments, and migration artefacts. Identify client opportunities, develop security‐focused points of view, and support account expansion. Understand … enterprise security programme design; and secure SDLC. Working knowledge of at least two cybersecurity frameworks: NIST CSF, NIST SP 800-53, ISO / IEC 27000 series, C2M2, or Cloud Security Alliance CCM. Familiarity with AI platform security, cloud and data security risks, and third‐party ...

Global Cybersecurity Manager - Client Assurance

Hiring Organisation
The Boston Consulting Group
Location
London, United Kingdom
Salary
£ 80 K
throughout all levels of the client organization, generating results that allow our clients to thrive.What You'll DoAs a Global Information Security Manager / Global Client Assurance Services Manager within BCG's Client Assurance Services (CAS) team, you will play an important role in supporting BCG's strategic clients … technical concepts clearly to non-technical audiences.Relevant professional certifications such as CISSP, CISM, CISA, Security+, or ISO 27001 Lead Auditor / Implementer are preferred.Strong communication, organization, and stakeholder management skills, with the ability to collaborate effectively across global and matrixed organizations.Prior experience in a professional ...

Technology Governance & Assurance Lead

Location
Greater London, England, United Kingdom
stakeholders to ensure controls are practical and aligned to business needs. The role requires extensive experience in tech assurance and governance, knowledge of NIST / COBIT / ISO 27001 / ITIL, and operation within a Three Lines of Defence model; you will design ...

Senior Vulnerability Management Engineer

Hiring Organisation
HCLTech
Location
City of London, London, United Kingdom
visit www.hcltech.com Job Title : Senior Vulnerability Management Engineer Location: London, UK ( Hybrid mode at client location ) Experience: 3 – 6 years in vulnerability management / information security ROLE SUMMARY The L2 Senior Vulnerability Management Engineer owns the organisation's end-to-end vulnerability management programme, spanning EUC, Data Center, Network … technology domains (endpoints, servers, network devices, web applications, cloud). • Design and maintain scan policies, asset groups, and scanning schedules in Qualys VMDR / Tenable Security Centre / Rapid7 InsightVM to ensure full coverage. • Perform risk-based vulnerability prioritisation: correlate CVSS scores with asset criticality, exposure, threat intelligence ...

Cyber Security Consultant (GRC)

Hiring Organisation
Oscar
Location
London, United Kingdom
Salary
£ 70 K
security governance and risk management frameworksReviewing the effectiveness of security controls and recommending proportionate improvementsAssessing clients against recognised standards and frameworks, including ISO 27001, NIST and similar methodologiesSupporting ISO 27001 implementation, readiness and assurance activitiesDeveloping risk registers, treatment plans, policies, standards … security consultancy, risk management or security assuranceA strong understanding of cyber security governance, risk and compliance principlesPractical experience working with frameworks such as ISO 27001, NIST, Cyber Essentials or similar standardsExperience conducting risk assessments, security assessments or compliance reviewsAn understanding of information security policies, controls, risk ...

Architect & Delivery Lead (68018)

Location
Greater London, England, United Kingdom
teams in London, Singapore, and Australia Define the automation strategy and prioritise cross‐tower automation initiatives for maximum cost and quality impact Establish SLA / KPI frameworks, performance dashboards, and outcome‐based metrics for all towers Lead the offshore migration strategy: define which roles move offshore, governance model … Technical Skills & Expertise Broad and deep technical knowledge across infrastructure, cloud, networking, security, IAM, SRE, and data engineering Expert‐level understanding of IaC, CI / CD, DevSecOps, GitOps, and platform engineering principles Architecture frameworks: TOGAF, cloud‐native architecture patterns, microservices, event‐driven design Cloud platform expertise across AWS, Azure ...

Senior Lead Oracle Fusion Cloud Integration & Extension Consultant role

Hiring Organisation
Version 1
Location
London, United Kingdom
Salary
£ 80 K
Year (EMEA)One of the Best Workplaces for Women in the UK & Ireland (2023) With 3,700+ people and revenues exceeding 347m / 302m, Version 1 is a market leader in Oracle, Microsoft, and AWS consulting services – and one of the fastest-growing digital consultancies in Europe. Job DescriptionWe … build, testing, deployment and defect resolution activities. The role also includes exposure to Oracle Fusion extensions and workflow tooling. VBCS, Oracle Process Automation (OPA) / Process Cloud Service (PCS) experience is desirable at junior level. The successful candidate should be willing and able to learn these areas quickly ...

Cyber Security Consultant (GRC)

Hiring Organisation
Oscar Technology
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£40,000 - £52,000 per annum
governance and risk management frameworks Reviewing the effectiveness of security controls and recommending proportionate improvements Assessing clients against recognised standards and frameworks, including ISO 27001, NIST and similar methodologies Supporting ISO 27001 implementation, readiness and assurance activities Developing risk registers, treatment plans … risk management or security assurance A strong understanding of cyber security governance, risk and compliance principles Practical experience working with frameworks such as ISO 27001, NIST, Cyber Essentials or similar standards Experience conducting risk assessments, security assessments or compliance reviews An understanding of information security policies ...

Head of Cyber Security

Location
Greater London, England, United Kingdom
financial services regulation, including FCA expectations for systems and controls, operational resilience, outsourcing, third-party risk, incident reporting, UK GDPR and client asset / data protection considerations Technology & Cloud Security: Broad knowledge of Microsoft security platforms, Azure security, endpoint protection, network security, email security, secure configuration, logging, monitoring … Lead Auditor, or equivalent Experience working with external auditors, penetration testers, MSSPs, cyber insurers, regulators, clients or supplier assurance teams would be beneficial Skills / Other relevant information Practical cyber leader who can move between executive discussion, technical detail and operational delivery without losing the thread Clear communicator ...

Information Assurance Analyst

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£540 - £590 per day
with: Business Continuity Management (BCM) Disaster Recovery Planning Operational Resilience Risk Management Frameworks Internal Audit Activities Control Assessments Process Improvement Programmes Familiarity with: ISO 27001 ISO 22301 NIST Cybersecurity Framework Cyber Assessment Framework (CAF) ITIL Governance, Risk and Compliance (GRC) tools Preferred Certifications … following certifications would be advantageous but are not essential: ISO 27001 Lead Auditor or Lead Implementer CISSP (Certified Information Systems Security Professional) CISM (Certified Information Security Manager) CRISC (Certified in Risk and Information Systems Control) ISO 22301 Business Continuity Certifications CIA (Certified Internal Auditor ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, United Kingdom
Salary
£ 80 K
designed, operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal / external audits, client reviews and due diligence.Oversee remediation plans and ensure continuous evidence collection.Develop consistent, lightweight playbooks for vendor intake, audit readiness and control … obligations.Manage and deliver risk and compliance training, including competency testing where appropriate.Support global data protection compliance (GDPR, CCPA and equivalents) as a data processor / service provider.Own vendor and third-party risk management, ensuring proportionate due diligence of suppliers, clients and acquisition targets.Reporting & Stakeholder LeadershipDeliver executive reporting on risk ...

Head of Information Security

Hiring Organisation
Picture More
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
continued development of its security capability. This is a broad leadership position covering everything from the outsourced SOC and incident response through to ISO 27001, Cyber Essentials Plus, cloud security, supplier assurance and the secure adoption of AI. What’s on offer: • Hybrid working, 3 days … continuous improvement • Strong experience managing outsourced SOC and specialist security providers • Excellent understanding of incident response, threat detection, vulnerability management and remediation • Strong Microsoft / Azure, cloud, infrastructure and SaaS security knowledge • Experience providing security assurance across technology projects and architecture • Understanding of UK GDPR, data protection and regulatory ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, UK
Employment Type
Full-time
designed, operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal / external audits, client reviews and due diligence. Oversee remediation plans and ensure continuous evidence collection. Develop consistent, lightweight playbooks for vendor intake, audit readiness … deliver risk and compliance training, including competency testing where appropriate. Support global data protection compliance (GDPR, CCPA and equivalents) as a data processor / service provider. Own vendor and third-party risk management, ensuring proportionate due diligence of suppliers, clients and acquisition targets. Reporting & Stakeholder LeadershipDeliver executive reporting ...

Head of Platform Engineering (up to £225k)

Location
Greater London, England, United Kingdom
first platform leader, defining the entire cloud strategy and building the team from scratch. You'll own the architecture, scale their Azure / AKS environment, and implement the security and compliance measures (SOC 2, ISO 27001, GDPR) that enable a product handling sensitive financial data. … full mandate, significant resources, and no inherited legacy. The work Define and drive the end-to-end cloud strategy, architecting and scaling the Azure / AKS environment for demanding financial-services deployments. Build and lead the platform engineering team from the ground up, setting the technical bar and culture. ...

Threat Detection Engineer - Hybrid / Remote

Hiring Organisation
Additional Resources
Location
London, United Kingdom
Salary
£ 70 K
Reference: SBM / AR / 070319Job Type: PermanentSalary: 60,000 - 80,000Location: Westminster, Central LondonSector: ITPosted: 2026-05-08Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare.We’re looking for a Threat Detection Engineer … focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale.This role offers hybrid / remote working options, a salary range of 60,000 - 80,000 and benefits.Why This Role is ExcitingHigh autonomy: Lead projects from idea to deploymentInnovation-driven: Develop ...

Infrastructure/DevOps Engineer

Location
Greater London, England, United Kingdom
high-performing. In this senior role, you’ll lead DevOps, observability, and compliance. Tasks include architecting cloud infrastructure for growth, prepping for SOC 2 / ISO 27001 audits, and setting up CI / CD pipelines for all services. You’ll also manage logging, metrics … knowledge. Networking concepts (VPCs, DNS, load balancers, VPNs, firewalls). Database management (PostgreSQL, MySQL, NoSQL) and storage. Python or Bash skills. SOC 2, ISO 27001, or GDPR exposure. Report directly to the founders with a chance to shape their future. Got what it takes? Apply ...

Cyber Security Consultant (Penetration Tester)

Hiring Organisation
Moore Kingston Smith
Location
London, United Kingdom
Salary
£ 50 K
technical capability.Skills, Knowledge and ExpertiseEssentialProfessional experience delivering client-facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and / or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali Linux … script or automate tasks using Python, PowerShell, Bash, or a comparable language.Good knowledge of modern web architecture, common web and API vulnerabilities, TCP / IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths.Experience delivering, or the ability to deliver, wider technical assessments such ...

Cyber Security Architect & Engineering Lead

Location
Greater London, England, United Kingdom
Security Architect & Engineering Lead Department: IT Infrastructure Employment Type: Permanent - Full Time Location: City, London Reporting To: Head of Information Security Compensation: £75,000 / year Description We are looking for a senior, hands-on Cyber Security Architect & Engineering Lead to help shape and strengthen our future security architecture … exposure management, using business risk, exploitability, attack-path context and threat intelligence to prioritise remediation. Support the technical implementation and evidence required for ISO 27001, Cyber Essentials Plus, client assurance and other regulatory or contractual obligations. Provide clear, risk-based technical advice to senior leaders, project ...

Cyber Security Consultant (Penetration Tester)

Hiring Organisation
Moore Kingston Smith
Location
London, UK
Employment Type
Full-time
technical capability. Skills, Knowledge and ExpertiseEssentialProfessional experience delivering client-facing penetration tests across web applications, APIs, and internal or external network infrastructure, independently and / or as part of a team. Strong manual testing capability and sound judgement in selecting and using automated tools, with practical experience of Kali … script or automate tasks using Python, PowerShell, Bash, or a comparable language. Good knowledge of modern web architecture, common web and API vulnerabilities, TCP / IP, Windows and Linux security, and Active Directory and Microsoft Entra ID attack paths. Experience delivering, or the ability to deliver, wider technical assessments ...

Enterprise Infrastructure Engineer

Hiring Organisation
Boku
Location
London, United Kingdom
Salary
£ 80 K
governance.Practical experience writing and maintaining Terraform for Infrastructure-as-Code.Experience building automation or workflow solutions using Microsoft Power Platform, including environment management and CI / CD pipeline creation and design.Strong scripting ability in Python and PowerShell.Strong hands-on experience configuring and administering Microsoft Intune (policies, compliance, app deployment, patching … such as OpenAI and Anthropic, and how they can be applied to infrastructure and operational workflows.Familiarity with Cloudflare, including Zero Trust and related network / security services.Experience in a global or enterprise IT environment operating across multiple regions.Familiarity with compliance frameworks such as ISO 27001 ...